Total app-ocalypse.
Why do apps need me to be authenticated against iTunes to work at all?
Total app-ocalypse.
Why do apps need me to be authenticated against iTunes to work at all?
I guarantee that someone would be screaming at Apple for not authenticating against iTunes under circumstance X, Y or Z.
I'm not sure whether it's better to be inconvenienced for a day, or for Apple to attempt to cover your back if something looks amiss in the iPhone's systems.
(which, from the sounds of your upgrade and hard crash, this may well be - or "simply" some form of empty cache)
It feels a bit like six of one, and half a dozen of the other, the painful bit being that ideology doesn't help you get your work done today!
With standard TOTP, you could pull out a paper backup and use it to make any TOTP app on any platform work. But with Authy, you're screwed if they're down.
And it sounds like you're screwed right now because Apple is down. Again, this wouldn't be an issue if you were using standard TOTP.
Meanwhile, if I'd given in and setup 2FA on my company's CloudFlare account, I wouldn't be able to access it right now.
So yes, I have an axe to grind -- with CloudFlare. We pay you $200/month, and the only reason we can still access our account is because I've refused to setup 2FA on it with Authy.
That's not the case. I'm in that position because of the fact that I got my phone into a bad state and can't reauth to iTunes. Others in the office have no problem at all and by talking to the technical support guys I know that I'm in an unusual position otherwise our customers would be very upset.
So yes, I have an axe to grind -- with CloudFlare. We pay you $200/month, and the only reason we can still access our account is because I've refused to setup 2FA on it with Authy.
What exactly is wrong with Authy that makes it completely unacceptable for you to use?
Let's turn this device into a secure token
Enter your Authy cellphone
__+code__ __Authy cellphone number__
They're my private tokens. I don't want to set up an account with Authy Inc and I certainly don't want my tokens in your cloud. Sure maybe it'd be nice to sync across my devices, but not if it looks like it means doing so via somebody else's servers!Do you not trust them to actually encrypt the data before backup? Or is there another issue?
Authy is a third-party authentication provider, it is not simply a synchronization service.
But the real issue for me is: given a choice between (1) having my private tokens physically only on my own devices; (2) having an account and apparently some form of my tokens at a third party in another country susceptible to bulk espionage and subpoenas... why on earth would I choose (2) in today's climate?
Or in summary: I guess I don't trust them to actually encrypt anything in the face of legal threats.
This exact scenario is sufficient on its own. Also individually sufficient are the unnecessary revelation of personal information to Authy, and an aversion to perpetuating an authentication method that unsophisticated users can easily confuse with more secure methods that don't rely on third parties.
None of these tools have any form of lock-in, but Apple imposes its own layer, in this case.
Authy works as a third-party authentication provider. Their servers are in the loop on every login. They aren't just a TOTP app + synchronization, they actually do the code validation themselves.
The correct analogy would be if every time you went to a website in Firefox, it asked Mozilla's servers if it was OK to go there. Also if, when installing Firefox, it demanded you create an account and give your cell phone number to Mozilla. (Or better yet, Google.)
So your scenario isn’t even that far off.
With regard to the others, there are crucial distinctions:
* Chrome synchronization is entirely optional. You can use Chrome without ever logging into Google's servers. That's not the case with Authy.
* The malware blocklist feature uses data stored on your local machine that is frequently updated from Google's servers. It does not send the URLs to Google. Even aside from privacy implications, that would be annoyingly slow. And the block can be bypassed (last time I saw it, anyway) with a single click.
Does this mean you normally can't ever use 3rd-party apps in airplane mode? Because that is definitely not the case for me.
Either that or grab a cheap Android handset and use it as a backup. The standard 2FA app on Android needs nothing more than occasional network connectivity to keep the clock in sync. You don't even need a Google account, the app is on FDroid.
Cloudflare is huge and many of us rely on it, so I hope you can easily avoid this predicament in the future - good luck!
I very strongly recommend against doing this: If you do that, you are giving up a lot of security provided by that second factor as the malware you are using 2FA to protect against now also has access to the keys used to create the 2FA token.
If your machine is compromised, it's over.
It can just forward code, relay cookies, etc. 2FA protects against someone peeking at your keyboard, or reused passwords, not malware.
I recently learned that there is an authenticator in f-droid, but not the authenticator, if one reads the notes at the top of the f-droid listing: https://f-droid.org/repository/browse/?fdid=com.google.andro...
I don't even know what they would want to stick in the Play store's authenticator above the already open sourced functionality.
[0] https://github.com/google/google-authenticator-android/wiki [1] https://play.google.com/store/apps/details?id=com.google.and...
Of these I have only tested "Mac App Store" and "Apple Support" and they don't seem to work.
I could log into the Apple Store though.
It is an interesting variation of the Airplane situation, but no connection is no connection.
Hopefully these lessons teach us that single points of failure are bad.
Using the code does work, so I don't think it's Duo.